Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into vulnerable form fields. When a user opens a page containing such a field, the attacker’s JavaScript runs in the victim’s browser, enabling data theft, session hijacking or defacement. The flaw changes scope, meaning the injected payload may affect resources beyond the original origin.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. The vulnerability exists in form fields that accept user input without proper escaping or sanitization.
Risk and Exploitability
The CVSS score of 5.4 classifies the issue as low‑to‑moderate risk, while the EPSS score of less than 1% suggests very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Likely attack vectors involve users who are allowed to submit data through the vulnerable forms, and the exploit requires only basic user interaction without privileged access.
OpenCVE Enrichment